CVE-2026-84665: Jenkins Project Jenkins Sonarqube Scanner Plugin

High severity, CVSS 8.0. EPSS: 0.4% chance of exploitation in the next 30 days.

Jenkins SonarQube Scanner Plugin 2.18.3 and earlier does not limit URL schemes for the dashboard links it creates based on SonarQube scanner results, allowing the `javascript:` scheme, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.

Affected products

  • Jenkins Project Jenkins Sonarqube Scanner Plugin: up to and including 2.18.3

Published 2026-09-02. Last modified 2026-09-03.